Hybrid Machine Learning and Deep Learning Approaches for Anomaly Detection Using KD99 and TON_IoT Datasets

Shahriar Ahmed, Saiful Islam, Md. Shahid Ullah · 2025

Anomaly detection is critical for safeguarding modern network and IoT environments against cyberattacks. This study investigates hybrid machine learning and deep learning approaches for anomaly detection using the KD99 and TON_IoT datasets. The proposed hybrid model integrates Decision Trees, XGBoost, and Convolutional Neural Networks (CNNs) to leverage their respective strengths: interpretability, handling imbalanced data, and learning complex patterns. Engineered features, such as prevPred, derived from Decision Tree outputs, further enhance model precision and recall. Experiments were conducted on both datasets, with cross-dataset evaluations testing the models' generalizability. Results demonstrate that the hybrid workflow achieved superior accuracy and robustness, outperforming standalone models across both datasets. On KD99, XGBoost achieved 99.2% accuracy, while CNNs excelled on the complex TON_IoT dataset with 96.8% accuracy. The hybrid model consistently delivered the highest performance, with accuracy exceeding 94% in cross-dataset evaluations. Despite the increased computational cost, the trade-off is justified for high-resource environments, where accuracy and adaptability are priorities. This study addresses limitations in cross-dataset learning observed in existing research and highlights the benefits of combining machine learning and deep learning models for anomaly detection. Practical implications include the deployment of hybrid models in real-world intrusion detection systems (IDS), where precision, efficiency, and adaptability are critical. Future work will focus on testing the models on additional datasets, exploring advanced architectures such as transformers and GANs, and implementing real-time detection in streaming environments.

Read the paper · More papers on PaperTik